Hackers breach FSB contractor, expose Tor deanonymization project
111–120 of 123 posts
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#112Earlier quoted context omitted.
>Not a single intelligence agency or diplomatic service will rely on ToR for security that’s madness... For the most part any country which can perform intelligence collection out of its embassy will have sufficient budget and and technical capacity to develop their own secure means of phoning home. The CIA has it's own onion service: ciadotgov4sjwlzihbbgxnqg3xiyrg7so2r2o3lt5wz5ypk4sxyjstad.onion Tor was developed by…
Wow I wonder how much compute it took them to generate that hidden service name.
I don't know how much the longer .onions affects generation time - anyone?
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#113Earlier quoted context omitted.
Wow I wonder how much compute it took them to generate that hidden service name.
I tried one of the older, shorter .onion addresses once out of interest. Didn't take long on a laptop to get a specified 7 characters at the beginning. I don't know how much the longer .onions affects generation time - anyone?
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#114Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…
How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)
How much it does so might be, and what it talks certainly is, but that's easily fixed by getting a line with dedicated bandwidth, running an encrypted connection (VPN or something custom) over it, and padding the traffic to ensure the bandwidth usage is constant (if you have a 100 Mbit line and 10 Mbit of traffic, you send 90 Mbit of padding).
The keys for the VPN get delivered via diplomatic courier.
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#115What is the risk of hosting an exit node? I have heard that you can be liable for facilitating illegal actions if yours gets used for it
When there's bomb threats, child porn, or other illegal activity coming from your home IP, you're going to get raided before you get to explain what a Tor node is.
When that stuff is coming from a server that you personally have rented, you're probably going to get raided before you get to explain what a Tor node is.
When that stuff is coming from a server that a company, student club, or similar has rented, suddenly brains are required to be switched on since there isn't an "obvious culprit", and it's unlikely that they'll start raiding the private homes of random members or organizers. Not impossible, but significantly less likely. The office address of the company/club is at the highest risk, but if that's "digital freedom club, computer science department building, university road 17, biguniversity" that's not necessarily a big problem. A raid at the office address would already be the exception, not the rule, but if you can make sure that a raid happening wouldn't be more than a minor annoyance, do it.
For non-exit nodes, just run them wherever you feel like, as long as you're OK with the traffic and the risk that some people will treat the IP as "not reputable". Anyone who finds the IP of the node will by necessity have an idea how Tor works and understand that the node is not the origin of the traffic.
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#116Earlier quoted context omitted.
> that an investigation itself can be damaging This is the main part. It's extrajudicial punishment. TONS of governments engage in this behavior. This is why MJ as illegal for so long. It allowed the US to imprison 1M more minorities since the 80s.
I agree with the principle of your point re: marijuana in specific -- it was often used as a way to stack charges, and especially in a racialized way. But I'm not sure it applies here. Clearly if the US is investigating a serious computer crime that came from your server, they can't take it on your say-so that it actually came from somewhere else. They need to be able to investigate. And typically for forensic reason…
In many other countries, crime reporting has to happen in an anonymized way until conviction.
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#117Earlier quoted context omitted.
I tried one of the older, shorter .onion addresses once out of interest. Didn't take long on a laptop to get a specified 7 characters at the beginning. I don't know how much the longer .onions affects generation time - anyone?
Is there a script to do that or did you roll your own?
For the longer v3 .onions you'll want a different tool, this page mentions some and makes some estimates for finding increasing lengths of characters: https://www.jamieweb.net/blog/onionv3-vanity-address/
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#118Earlier quoted context omitted.
Controlling just the exit nodes doesn't mean much, but by controlling the majority of all nodes you break TOR. If I controll all nodes your connection uses I can trivially deanonymize you (even if you use hidden services). It has also been shown multiple time that it is enough to control the first and the last node of the connection because timing correlation works great. The upside is that no government would admit…
Running Tor exit node is dangerous. Very few people would dare to do so. Most of hosters will forbid that. Now running ordinary Tor node is not dangerous. It does not consume a lot of resources (I'm running node on 256 MB OpenBSD VPS) and hosters don't care at all. It takes few minutes to install and set it up. So there's absolutely no reason for people not to run Tor node on every server they have access to. And I'm…
There is at lest one: list of tor relays IP addresses is public. Some mail servers use this list as an additional source for RBLs (probably people, who are not familiar with tor don't know the difference between exit nodes and relays and bun all just in case). So it is not a good idea to share mail server IP with a tor relay.
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#119Earlier quoted context omitted.
I feel like if I were a network operator for something that sensitive I might send some bursts of traffic to nothing just to keep anyone trying to infer "lots of traffic" → "something going on" on their toes. (Though certainly things like packet timing, packet size, etc. might make more thorough analyses harder to escape…)
A highly secure connection either uses a fixed-bandwidth pipe or constantly sends random data to avoid correlation like this.
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#120Earlier quoted context omitted.
This is a silly conspiracy. The facts about the initial funding of research on Tor have always been public and well-known, and the conspiracy is based on the idea that there was some grand scheme looking forward into the future for more than 16 years. It's much more likely that some researchers at some government agency implemented the known idea of onion routing in a proof of concept, their work was more successful…
Yeah, just because something was either invented or first implemented in the military doesn't mean it's tainted forever. SQLite was originally designed to be used on ballistic missiles. Heck, the internet itself was first developed by the DoD (ARPA). A lot of technologies have military origins.
[1] https://www.amazon.com/Corruption-Malcolm-Gladwell-Yasha-Lev...